4.4.2. Management of External Services
💡 First Principle: A vendor's risk to your organization doesn't freeze at the moment the contract is signed — it changes for as long as the relationship continues, which means oversight has to continue for the life of the relationship, not just at onboarding.
Due diligence at procurement (security questionnaires, control attestations, right-to-audit clauses negotiated into the contract) answers "was this vendor acceptable when we signed." It says nothing about whether that vendor's security posture, ownership, or subprocessor list has changed in the eighteen months since. Ongoing third-party risk management — periodic reassessment, monitoring for security incidents at the vendor, and enforcement of SLA security requirements — is what keeps that initial due-diligence snapshot from silently going stale.
⚠️ Exam Trap: Vendor risk management is sometimes assumed to end once due diligence is completed and the contract is signed. The correct answer requires ongoing monitoring and periodic reassessment for the life of the relationship, not just onboarding.
Reflection Question: A critical vendor passed rigorous due diligence three years ago and hasn't been reassessed since. What could have changed at that vendor in three years that your organization currently has no visibility into?